It doesn't take anything near DDoS. If you dare to put up a website that serves images from S3, and one guy on one normal connection decides to cause you problems, they can pull down a hundred terabytes in a month.
Is serving images from S3 a crazy use case? Even if you have signed and expiring URLs it's hard to avoid someone visiting your site every half hour and then using the URL over and over.
> AWS is just charging you for how much it served, it doesn't make sense to hold them to a fault here.
Even if it's not their fault, it's still an "inherent vulnerability of S3 pricing". But since they charge so much per byte with bad controls over it, I think it does make sense to hold them to a good chunk of fault.
Do you expect DDoS protection to kick in from one person downloading a single digit number of images per second?
It should be possible to use the service, especially common ones like S3 with little knowledge of architecture and stuff.
S3’s simple setup (which denies all public access) is not flawed in the manner being discussed here. Allowing public direct access to an S3 bucket is a supported option, but for years has been both non-default and strongly recommended against.